Executive brief
A spoofing vulnerability exists in the Windows CryptoAPI (Crypt32.dll) due to improper validation of Elliptic Curve Cryptography (ECC) certificates. Attackers can exploit this to sign malicious executables with spoofed certificates or conduct man-in-the-middle attacks to decrypt confidential information. The vulnerability is also known as 'CurveBall'.
Affected products
- Microsoft Windows 10 1607, 1709, 1803, 1809, 1903, 1909, 1507
- Microsoft Windows Server 2016 - , 1803, 1903, 1909
- Microsoft Windows Server 2019 -
- Golang Go 1.12 to 1.12.16, 1.13 to 1.13.7
Timeline
- 2020-01-14: advisory: MSRC advisory published (based on CVE ID year and typical patch cycle)
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed